Commit Graph
74 Commits
Author SHA1 Message Date
Michael Eischer 420c4c6683 Add changelog for fsync warning 2023-05-13 22:05:18 +02:00
Michael Eischer be14687a9c Print fsync warning only once
The repo.Handler is freshly instantiated for every request such that it
forget that the fsync warning was already printed. Use a single instance
in the Server instead.
2023-05-13 21:50:39 +02:00
Michael Eischer b2e8044fbd Fix inverted condition for fsync warning
The warning should only be printed if fsync is _not_ supported and not
the other way around.
2023-05-08 21:40:23 +02:00
Michael Eischer 30ec84fcb7 Merge pull request #228 from MichaelEischer/update-ci
Update CI configuration and verify changelog entries
2023-05-05 23:05:22 +02:00
Michael Eischer 2a3bca1633 Fix type of changelog entry 2023-04-30 15:21:16 +02:00
Michael Eischer aeb5e2982f CI: Automatically check changelog entries 2023-04-30 15:18:44 +02:00
Michael Eischer 20c4cdedfc CI: Sync tests with restic 2023-04-30 15:18:28 +02:00
Michael Eischer c064e4c1ed Merge pull request #217 from HeikoSchlittermann/feat-log-to-stdout
feat: allow logging to stdout, stderr
2023-04-30 14:56:29 +02:00
Michael Eischer 66fe4afb7d Make changelog less technical 2023-04-30 14:51:46 +02:00
Michael Eischer 4576e1bc12 Fix docker container setup for goreleaser
The expected approach is that the binary built by goreleaser is added to
the docker container.
2023-04-28 20:41:30 +02:00
Michael Eischer e8a839673f Set development version for 0.12.0 2023-04-27 21:41:32 +02:00
Michael Eischer b34b9f0780 create folder for unreleased changelogs 2023-04-26 21:09:55 +02:00
Michael Eischer 253bebb096 Merge pull request #225 from restic/dependabot/go_modules/github.com/prometheus/client_golang-1.15.0
Bump github.com/prometheus/client_golang from 1.14.0 to 1.15.0
2023-04-22 11:23:51 +02:00
Michael Eischer 337035c414 Merge pull request #221 from MichaelEischer/skip-files-in-intermediate-directories
Ignore unexpected files in intermediate directories
2023-04-22 11:20:11 +02:00
Michael Eischer afcdb2f312 Merge pull request #224 from restic/dependabot/go_modules/github.com/spf13/cobra-1.7.0
Bump github.com/spf13/cobra from 1.6.1 to 1.7.0
2023-04-11 22:42:58 +02:00
Michael Eischer da9ce53a95 Merge pull request #223 from restic/dependabot/go_modules/golang.org/x/crypto-0.8.0
Bump golang.org/x/crypto from 0.7.0 to 0.8.0
2023-04-11 22:38:43 +02:00
Michael Eischer 3a23555594 Merge pull request #202 from deajan/patch-1
Make dashboard portable
2023-04-08 21:22:22 +02:00
Michael Eischer 22a6412b81 Ignore unexpected files in intermediate directories
Listing the data/ folder in a repository no longer fails if it contains
files in the data/ folder. This also ignore .DS_Store files created by
macOS.
2023-04-08 20:17:44 +02:00
Michael Eischer 11c5a548e8 Merge pull request #216 from restic/dependabot/go_modules/golang.org/x/crypto-0.7.0
Bump golang.org/x/crypto from 0.6.0 to 0.7.0
2023-04-08 19:34:33 +02:00
Michael Eischer c3d3bfbc12 Merge pull request #218 from restic/dependabot/github_actions/actions/setup-go-4
Bump actions/setup-go from 3 to 4
2023-04-07 12:35:13 +02:00
Michael Eischer ea461a2d76 Merge pull request #214 from restic/dependabot/go_modules/golang.org/x/crypto-0.6.0
Bump golang.org/x/crypto from 0.5.0 to 0.6.0
2023-02-19 13:54:43 +01:00
Michael Eischer 8f3b92325f Merge pull request #213 from 0xpr03/patch-1
warn about SystemCallArchitectures in the systemd service
2023-02-10 21:44:18 +01:00
Michael Eischer 667ce6e26b Merge pull request #210 from ph818/patch-1
add MemoryHigh to systemd example
2023-01-26 22:36:29 +01:00
Michael Eischer f5c06a2e45 Merge pull request #208 from MichaelEischer/upgrade-dependencies
Upgrade dependencies
2023-01-20 22:42:58 +01:00
Michael Eischer 40e2a8b1e4 add changelog and update readme 2023-01-20 22:36:40 +01:00
Michael Eischer fa795cc66a upgrade go-systemd to latest major version 2023-01-14 21:00:32 +01:00
Michael Eischer 99ec5e2dbb CI: update and sync ci tasks with restic 2023-01-14 20:39:32 +01:00
Michael Eischer f299c735df bump minimum go version to 1.17 2023-01-14 19:22:08 +01:00
Michael Eischer 8ce88b24e7 enable dependabot 2023-01-14 19:18:10 +01:00
Michael Eischer 2eae8c9266 update transitive dependencies 2023-01-14 19:17:53 +01:00
Michael Eischer 30fbd043b9 update direct dependencies 2023-01-14 19:09:42 +01:00
Michael Eischer 7f29dcbd69 Merge pull request #207 from MichaelEischer/err-on-args
Error out on unexpected command line argument
2023-01-12 22:00:36 +01:00
Michael Eischer 43c96fb6f2 Error out on unexpected command line argument
rest-server doesn't accept arguments. Thus, error out to prevent wrong
usage.
2023-01-11 21:47:25 +01:00
Michael Eischer a8cd3f218d Merge pull request #199 from MichaelEischer/support-macos-ventura
Ignore fsync errors
2022-12-16 23:13:43 +01:00
Michael Eischer 80babf98e7 add fsync warning 2022-12-02 21:08:15 +01:00
Michael Eischer 408dcab92e Port fsync error handling from restic
This ignores several different combinations of errnos which are returned
if the storage destination is not able to fsync correctly.

See also https://github.com/restic/restic/pull/4021
2022-11-11 22:37:02 +01:00
Michael Eischer f763db8934 Deduplicate handler initialization in tests 2022-09-02 23:41:05 +02:00
Michael Eischer a8fdca3b9f make deleting idempotent 2022-09-02 23:32:52 +02:00
Michael Eischer b562edefd1 add changelog for not found error handling 2022-08-31 22:29:14 +02:00
Michael Eischer cb2afaa4c0 test that inaccessible files result in status 'internal error' 2022-08-31 22:29:14 +02:00
Michael Eischer 991c459be3 Only return "Not Found" status if file does not exist
All other errors are now turned into a internal server error and are
logged.
2022-08-31 22:29:14 +02:00
Michael Eischer 65fd8be3f8 Add changelog for cached basic auth 2022-07-02 21:17:57 +02:00
Michael Eischer 274f29fee8 refactor password check into separate function 2022-06-21 00:18:05 +02:00
Michael Eischer 98f0aaca1c convert htpasswd regexes to globals 2022-06-21 00:18:05 +02:00
Michael Eischer 5a6ed2ffdf use constant time comparison for sha1 password hash 2022-06-21 00:18:05 +02:00
Michael Eischer 46b020fd9e Add basic test 2022-06-21 00:18:05 +02:00
Michael Eischer df9eb337d3 Extend htpasswd auth cache entry expiry on use 2022-06-21 00:18:05 +02:00
Michael Eischer 1eeca53812 Try to zero htpasswd cache entries before deletion 2022-06-21 00:18:05 +02:00
Michael Eischer 0bdc420e75 Cache successful basic auth credentials for a minute
This stores a hash of the username + password in map which is indexed by
the username. Indexing by username avoids accidentally introducing a
timing side-channel as a successful/failed lookup only provides
information on whether a cache entry exists for a username or not.

Hashing the username and password together makes it simple to get a
constant-time string comparison as we no longer have to worry about
string length differences.

Expriy is done by a goroutine which every few seconds checks for expired
cache entries and removes those.
2022-06-21 00:18:05 +02:00
Michael Eischer b0036d006b Unexport users map in htpasswd struct 2022-06-21 00:18:05 +02:00
Michael Eischer 228d5f6051 Reword changelogs 2022-02-10 19:48:44 +01:00
Michael Eischer aaf4f4b92a Update dependencies
This also cleans up the indirect dependencies.
2022-02-08 22:55:00 +01:00
MichaelEischer 421da62900 Merge pull request #156 from telenieko/patch-1
Clarification of docker section in README.md
2021-10-31 19:33:41 +01:00
Michael Eischer 51ab8e98e2 fix file permission handling 2021-09-24 23:10:16 +02:00
MichaelEischer 9f8c31b968 Merge pull request #158 from Enrico204/use-os-tempdir-for-temporary-directory
Use os.TempDir() for temporary directory in default path
2021-09-12 21:30:59 +02:00
Michael Eischer f952bc7344 Tweak readme 2021-09-12 21:27:45 +02:00
MichaelEischer 1172d7e068 Merge pull request #160 from Enrico204/reply-with-insufficient-storage-on-disk-full
Reply "insufficient storage" on disk full or over-quota
2021-09-07 21:28:07 +02:00
MichaelEischer 8729a699a1 Merge pull request #164 from networkException/master
Config: Read in PrometheusNoAuth correctly
2021-09-04 13:27:46 +02:00
MichaelEischer 8642729a51 Merge pull request #163 from buschjost/optimized-sha256-lib
Use Minio's optimized SHA-256
2021-08-31 21:04:25 +02:00
MichaelEischer 5be12cecbf Merge pull request #143 from MichaelEischer/docker-create-bcrypt
docker: use bcrypt in create_users script
2021-08-23 20:10:38 +02:00
Michael Eischer 20edfb87ee docker: use bcrypt in create_users script
This was missed when adding bcrypt support in rest-server 0.9.7
2021-08-20 22:52:03 +02:00
Michael Eischer 64a43228de Prefix temporary file with object id 2021-08-12 22:17:49 +02:00
Michael Eischer 28f569c0df Add changelog 2021-08-12 22:15:08 +02:00
Michael Eischer ec0766cddd Don't sync directory on Windows
Calling sync on a directory on Windows just returns "The handle is invalid"
and fails.
2021-08-12 22:14:36 +02:00
Michael Eischer 2175029c9e Sync directory to disk after upload
After a file was uploaded, also sync its containing directory to disk to
make sure that also the directory entry is persisted after a system
crash.
2021-08-12 22:08:08 +02:00
Michael Eischer 82816c67e1 Atomic upload for blobs
A upload is now first saved to a temporary file before it gets renamed
to the final filename. This ensures that incomplete uploads don't leave
broken files behind (at least not under their real filename).

In addition, removing failed uploads is no longer prone to a race
condition with a retried upload. That scenario could occur when the
first upload fails partway and the server doesn't notice that
immediately. A later retry by restic will then delete the broken upload
and upload the file again. If the server notices now that the initial
upload has failed, then it will delete the correctly uploaded file.

This has been fixed by only ever deleting the temporary file during
upload.
2021-08-12 22:06:08 +02:00
Michael Eischer 16889717c6 Add option to disable integrity check on upload 2021-08-09 15:40:50 +02:00
Michael Eischer 54adcb1fc7 Verify uploaded files
Restic uses the sha256 hash to calculate filenames based on the file
content. Check on the rest-server side that the uploaded file is intact
and reject it otherwise.
2021-08-09 15:35:13 +02:00
MichaelEischer c36ae5fe03 Merge pull request #149 from tim-seoss/systemd-unit-file-enhancement
Improve security of example systemd unit file
2021-06-05 14:37:42 +02:00
MichaelEischer 1ca9ca7e50 Merge pull request #124 from lwis/update-docker
Fix Docker configuration for DISABLE_AUTHENTICATION
2021-05-15 18:39:42 +02:00
Michael Eischer 766f1e0c00 Revert dockerfile changes and cleanup changelog 2021-05-15 18:31:01 +02:00
MichaelEischer a44c025cd3 Merge pull request #145 from jinnko/master
Build restic at container build time
2021-05-13 20:00:20 +02:00
Michael Eischer 73fb6419ff Tweak changelog 2021-05-13 19:49:25 +02:00
Michael Eischer 0a6e0dbdf9 Properly close CPU profile on sigint
The rest server is normally shutdown via a SIGINT signal. The http
handle calls are endless loops and don't return in the normal case. Thus
add a signal handler to shutdown the profiler.
2021-01-03 20:16:54 +01:00